Artificial intelligence is often governed as if it were a machine sitting apart from the institutions that build and use it. Regulators, companies and standards bodies ask whether a model is fair, explainable, safe, robust, secure and aligned with human values. But a new conceptual article argues that this approach misses the most important actor in the system: the corporation. The company pays for the data, chooses the model, determines where it will be deployed, extracts commercial value from its outputs and possesses the authority to suspend or abandon it. In “Governing the AI-mediated corporation: corporate governance and the limits of detached AI governance,” published in AI & Society, Kei Nakagawa proposes that responsible AI governance must focus not only on the technology, but also on the corporate institution acting through it.
The argument shifts attention from AI as an isolated technical object to what Nakagawa calls the “AI-mediated corporation.” This is a company whose decisions, communications, employment practices, customer interactions and internal operations are increasingly shaped by algorithmic systems. The AI may recommend a candidate, generate an answer for a customer, rank a business opportunity, detect fraud or assist in product development. Yet these outputs do not become socially consequential until they are embedded in organizational authority. A prediction inside a laboratory is not the same as a prediction used to deny employment, alter a customer’s legal position or guide a company-wide investment. The corporation supplies the context in which an algorithm’s statistical output becomes a decision, a policy or a source of harm.
Most existing AI governance frameworks are designed around the system itself. Technical teams may test a model for disparate error rates, document its training data, measure its performance across demographic groups or conduct an audit after deployment. Management systems such as ISO/IEC 42001 and risk frameworks such as the NIST AI Risk Management Framework provide valuable tools for identifying and controlling these risks. Human-rights due diligence and emerging AI laws add requirements concerning transparency, risk assessment, oversight and impact mitigation. Nakagawa’s central claim is not that these instruments are unnecessary, but that they remain incomplete when detached from corporate governance. A model can pass a technical evaluation and still be deployed in a business process that gives employees no meaningful right to challenge it, rewards managers for ignoring warnings or transfers responsibility to an outside vendor.
To close this gap, the article develops an authority-benefit-capacity principle. The basic idea is that the institution that has the authority to create, procure, deploy, modify or stop an AI system, while also receiving benefits from it and possessing the capacity to prevent or repair resulting harms, should occupy the primary locus of governance. This principle does not mean that every company is solely responsible for every failure in an AI supply chain. Developers, vendors, managers, professional experts, regulators and users may each have distinct obligations. It does mean that a corporation cannot treat the model as an autonomous source of decisions when the organization controls the surrounding conditions. If a company chooses the objective function, sets the tolerance for false positives, approves the data, defines the workflow and decides whether human review is genuine or merely symbolic, the company remains institutionally answerable for the system’s operation.
The term “answerability” is important because it is different from several concepts that are often treated as interchangeable. Blame asks who deserves moral condemnation. Liability asks who may be legally required to pay damages or accept a sanction. Legitimacy asks whether an exercise of power is accepted as justified. Ordinary managerial accountability often concerns whether an individual followed internal procedures. Institutional answerability is broader: it asks which organization must explain what happened, disclose how a decision was made, respond to affected people, correct the process and provide a remedy. A corporation may be answerable even when no single employee intended harm and when the legal conditions for personal blame or liability are difficult to establish. This distinction is especially important for complex machine-learning systems, whose behavior can emerge from interactions among data, software, vendors, incentives and human decisions rather than from one identifiable act.
Nakagawa argues that corporate governance must therefore translate broad AI norms into concrete organizational mechanisms. A company’s board could treat material AI risks as a governance issue rather than delegating them entirely to engineers or a compliance team. Risk registers could connect model failures to specific business owners, budgets, escalation routes and stop-use authority. Procurement contracts could require vendors to disclose system limitations, preserve audit access and cooperate with investigations. Internal controls could record who approved a model, what evidence supported deployment, which groups might be affected and under what conditions the system must be withdrawn. Independent testing, incident reporting and post-deployment monitoring would need to be linked to decisions that management can actually take. Without this institutional connection, a fairness assessment may become a document, an ethics policy may become a public-relations statement and a human-in-the-loop requirement may reduce to a person clicking “approve” at the end of an automated workflow.
The article tests this argument through three public illustrations that represent different points in the corporate AI landscape. The first concerns internal development and employment: Amazon abandoned a recruiting tool after reports that it penalized résumés associated with women. The episode demonstrates that bias can arise not only from explicit design choices but also from historical data reflecting an organization’s previous workforce and hiring patterns. A model trained to reproduce past success may learn that male-dominated employment histories are signals of quality, even if gender is removed as a direct input. Technical adjustments may reduce some disparities, but governance must also address the business decision to automate screening, the incentives to process applications rapidly, the people responsible for validating the tool and the rights of candidates affected by its recommendations. The corporation is not merely a customer of an algorithm; it is the institution that turns the score into an employment opportunity or exclusion.
The second illustration is the Air Canada chatbot case, in which a customer relied on incorrect information generated by the airline’s conversational system and later obtained a remedy through a British Columbia tribunal. Chatbots generate language by predicting likely sequences of words from statistical patterns, not by possessing a guaranteed database of legally accurate policies. That technical fact does not relieve a company of responsibility when it presents the system as a customer-service channel. The critical governance questions include whether the chatbot’s claims were checked against authoritative information, whether users were warned about its limits, whether conversations were logged, whether a human escalation route was available and whether the company retained the power to disable the tool after errors. The incident illustrates a persistent agency gap: organizations may describe an AI system as independent when it performs well, but as merely experimental when it causes harm. Corporate governance must prevent this selective attribution of agency.
The third illustration involves vendor-mediated employment screening and the litigation surrounding Workday. Here, an employer may rely on a third-party platform whose algorithmic assessments influence hiring decisions, creating a chain of responsibility that crosses organizational boundaries. Outsourcing does not eliminate governance obligations. It can make them more difficult by obscuring training data, model design, validation procedures and the allocation of responsibility between the vendor and the employer. Effective oversight would require companies to understand the systems they purchase, evaluate their effects on applicants, maintain channels for explanation and challenge, and ensure that contractual arrangements do not make remedies practically impossible. It would also require attention to workers and applicants as participants in governance rather than merely data subjects. Labour representatives, affected communities and independent experts may identify risks that internal technical teams cannot see, particularly when an AI system changes the distribution of work, discretion and bargaining power.
The AI-mediated corporation also challenges conventional ideas about corporate agency. A company is not a human mind, but a structured collective capable of making decisions through boards, executives, policies, budgets and procedures. AI can alter that structure by accelerating decisions, distributing judgment across software and employees, and allowing corporate systems to act continuously at a scale no individual manager can supervise directly. This creates what the article describes as a need to redesign governance for AI-enabled forms of corporate agency. Human oversight cannot mean simply placing a person somewhere in the process. It must involve authority, competence, time, information and independence sufficient to question or stop an automated operation. Boards and senior managers must understand how AI affects the firm’s objectives and stakeholders, while employees need protected channels to report failures. Public regulation, market pressure, labour voice and supply-chain due diligence remain essential, but they work more effectively when the corporation itself is structured to receive warnings, disclose decisions and repair harm. The article’s broader message is that responsible AI will not be achieved by governing models alone. It requires governing the organizations that choose what models do, who benefits from them and who bears their risks.

